AI Governance, Risk & Red Teaming
Strategic · M13 · lesson 13 of 25 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
Building an AI Risk Heat-Map for the Audit Committee
📖
now learning

Building an AI Risk Heat-Map for the Audit Committee

15 min

Q2 audit-committee meeting, 09:14, Acme.Corp boardroom. The chair, a former Big-Four audit partner, is twenty-six minutes into the cyber-and-technology agenda when she sets down her pen, looks across the table at Acme's CRO, and asks the question he has been bracing for since the Article 73 incident on 22 April: "Show me the AI heat-map." The CRO has the cyber risk heat-map ready: twenty scenarios, 5×5 matrix, color-coded, vetted by the Big-Four auditor in March. He pulls it up. The chair waits eight seconds. Then: "That is the cyber heat-map. Where on it is the hiring AI fairness slice? Where is the Article 73 late-report scenario from April? Where is the agentic refund cascade we discussed in February? Where is the GPAI Article 51 threshold risk on our internal model? Where is the ISO 42001 surveillance audit risk? I do not see AI on this map. The board's audit-committee charter was amended in January to require AI-portfolio risk reporting. Please come back next quarter with an AI risk heat-map: same 5×5 grid, defensible likelihood and impact anchors, the full AI-portfolio scenarios plotted, twelve-month movement arrows, and the audit committee's prepared response for every red cell." The CRO has ninety days. This lesson is the playbook: the regulatory expectation (SEC, Dodd-Frank, SR 11-7, EU AI Act Article 17, board-AI-subcommittee charters), the 5×5 matrix structure, the anchored likelihood and impact calibrations, the twelve regulator-grade AI risk scenarios plotted with rationale, the eight-section briefing document, the six common failures to avoid, the fifteen audit-committee questions to anticipate, and the worked Acme Q2 2026 heat-map with seventeen AI systems plotted, scenario 7 (Article 73 late report) flagged as worst point, and three movement arrows toward amber. By the next quarterly meeting, the heat-map is on the audit-committee minutes, and the chair signs off.

Why an AI Risk Heat-Map Is a 2026 Audit-Committee Expectation

Through 2024 the audit committee's view of AI risk was typically a paragraph in the technology-risk update, sometimes a sub-bullet under cyber, sometimes absent entirely. That posture is gone in 2026. Five regulatory and supervisory developments converge on a single defensible visual, a 5×5 AI risk heat-map across the enterprise AI portfolio, and the audit committee chair who asks for it can now point to specific charter authority, SEC disclosure expectations, prudential supervision, and EU AI Act Article 17 documentation obligations.

  • SEC disclosure expectations under Items 105, 303, 407 and the 2023 cybersecurity rule extended into AI. The SEC's cybersecurity disclosure rule (effective 18 December 2023) requires risk-management and governance disclosures. Through 2025 staff commentary and 2026 sample comment letters have extended the same logic to material AI risks: board oversight structure, management's role, the risk-management process, and any material incident under Item 1.05 of Form 8-K. The audit committee is the board organ tasked with overseeing risk-management adequacy; absent a defensible AI risk artifact, the committee cannot attest to that adequacy in the proxy or 10-K. The heat-map is the artifact.
  • Dodd-Frank §165 enhanced prudential standards extended to AI as model and operational risk. For bank holding companies and designated nonbank financial companies, the Federal Reserve's enhanced risk-management standards require board-level risk-committee oversight with explicit risk appetite. As LLMs and agents enter the model-risk inventory in 2026, the briefing pack must include an AI-portfolio-level view. A heat-map calibrated to the enterprise risk appetite (lesson 074) is the standard form.
  • SR 11-7 model risk management framework, applied to AI portfolio. The Fed / OCC SR 11-7 framework names model risk as a discrete category and requires the board to be informed of aggregate model-risk position. As lesson 068 walked, LLMs and agents now sit in the model-risk inventory. The audit committee's expectation is a portfolio-level view, not a model-by-model deep dive, and the heat-map fits the committee's review cycle (45-90 minutes, 25-40 slides).
  • EU AI Act Article 17 (quality management) and Article 9 (risk management). Article 17(1)(a) requires a documented compliance strategy including modification management; Article 17(1)(b) requires risk-management procedures. Article 9 requires a continuous, iterative risk-management process. The heat-map is the load-bearing artifact for both: it demonstrates that risks are identified, calibrated, and tracked. Conformity assessment bodies in 2026 cross-reference the heat-map against the Annex IV technical-documentation file (Article 11) to test whether documented risks match operational evidence.
  • Board AI-subcommittee charters amended through 2025-2026. Approximately 35-50% of S&P 500 board charters were amended through 2024-2026 to include explicit AI-oversight language (Spencer Stuart Board Index 2025 + EY Center for Board Matters 2026). The amendments name the audit committee, the risk committee, or a newly-formed AI committee as responsible organ. In every case the charter requires periodic reporting on the enterprise AI risk portfolio. The heat-map is the standard format because it (a) fits a single page, (b) is defensible with anchored definitions, (c) shows trajectory, and (d) ties to risk appetite.

Why a heat-map rather than a risk register dump. The audit committee's review cycle is constrained, typically 45-90 minutes of AI-relevant agenda per quarter. A 200-row risk register is unreadable in that window. A 5×5 heat-map with 12-17 scenarios plotted is absorbable in 5-8 minutes, defensible under follow-up questioning, and is the artifact the chair can carry to the full board. The risk register remains the underlying source-of-truth; the heat-map is the briefing layer. The committee needs the picture, not the register.

The defensibility test. Before any heat-map lands on the audit-committee agenda, the AI Risk Office must pass a five-clause defensibility test. (1) Anchored definitions for every cell. "High likelihood" without a percentage anchor is not defensible against Big-Four challenge. (2) Named source-of-truth for every plotted scenario: incident history, red-team finding closure rate, vendor concentration analysis, threat-intel feed. (3) Trajectory arrows. A point-in-time map is half the artifact; the chair will ask "where is this going." (4) Tied to risk appetite. Every cell cross-walked to the board-approved AI risk appetite from lesson 074. (5) Refreshed quarterly with emergency-refresh capability. A static heat-map cannot survive a quarter with a material incident.

Heat-Map Structure: The 5×5 Matrix + Anchored Likelihood and Impact

The 5×5 matrix is the regulator-recognized form. Five likelihood levels on the vertical axis (Very-Low at the bottom to Very-High at the top), five impact levels on the horizontal axis (Very-Low on the left to Very-High on the right). Each cell carries a color: the four corners and four edges are calibrated to the enterprise color convention. The Acme convention used throughout this lesson, and recognized in NACD, IIA, and IRM-published heat-map guidance, is green (acceptable), yellow (monitor), amber (action plan), red (escalation), crimson (board-level decision).

Likelihood calibration, five anchored levels.

The single most common heat-map failure (Common Failure 1 below) is qualitative likelihood with no anchored definition. The audit committee chair pressing on "what does High mean" must hear a specific percentage band, a named historical reference, and the data sources that feed the band. The Acme calibration:

  • Very-Low, less than 2% per year. The scenario has occurred 0-1 times in the organization's history; cross-industry incident-tracker disclosures (AIAAIC, OECD AI Incidents Monitor, ISO/IEC 22989 incident classifications) show it occurring less than 5% of comparable enterprises per year; no current red-team finding or threat-intel signal indicates elevated near-term probability.
  • Low, 2-10% per year. Occurred 1-2 times in the organization's history or in the top quartile of comparable enterprises; one or more red-team findings open but with closure plan tracking on schedule; threat-intel signal is baseline.
  • Medium, 10-25% per year. Occurred 2-3 times in the organization's history; red-team findings open with closure-rate behind plan; vendor concentration or deployer-territory exposure elevated; threat-intel signal shows uptick (e.g., increase in similar adversary tradecraft observed in the wild).
  • High, 25-60% per year. Occurred 3+ times in the organization's history; red-team findings open and not on closure plan; multiple amber KRIs (lesson 074); active threat-intel signal; vendor concentration single-point-of-failure exposure unaddressed; near-term mitigations not yet operational.
  • Very-High, greater than 60% per year. Either already realized in the current quarter (likelihood now refers to a recurrence within 12 months) or red KRIs sustained across multiple periods with no on-plan mitigation; expectation is the scenario manifests within the trailing 12-month forward window.

Anchored to: (a) historical incident rate from the operational-risk loss-event database; (b) red-team finding closure rate (lesson 084); (c) vendor concentration analysis; (d) deployer territory exposure (EU/US/UK on the model in question, given differential penalty band); (e) threat-intelligence feeds: CAISI disclosures, EU AI Office bulletins, sector-ISAC AI-vertical reports, MITRE ATLAS technique-prevalence updates.

Impact calibration, five anchored levels combining six sub-impacts.

The impact dimension is the harder calibration because a single AI failure typically generates impact across multiple sub-domains simultaneously. The Acme calibration combines six sub-impacts: (i) consumer harm, fairness disparities, safety failures, fundamental-rights infringement; (ii) regulatory exposure, Article 99 penalty band, FTC enforcement, sectoral-regulator action; (iii) financial impact, direct loss plus revenue at risk; (iv) reputational, media reach, customer churn, NPS impact, social-media velocity; (v) operational, downtime, recovery cost, business-process disruption; (vi) ESG/strategic, investor-relations impact, ESG-rating downgrade, partnership-pipeline cooling.

The cell-level impact is the higher of the six sub-impacts (worst-case dominance). The five levels:

  • Very-Low impact. Consumer harm absent or single-handful affected with prompt remediation; regulatory exposure limited to administrative cure; financial impact under $100k; reputational impact contained to internal awareness; operational impact under 4 hours; ESG impact absent.
  • Low impact. Consumer harm to tens of users; regulatory exposure to formal-but-informal inquiry (no fine in normal course); financial impact $100k-$1M; reputational impact local press cycle; operational impact half-day to one-day disruption; ESG impact limited to single-quarter analyst note.
  • Medium impact. Consumer harm to hundreds-thousands; regulatory exposure to enforceable cure order or sub-band penalty (Article 99(4) administrative fines, FTC consent decree); financial impact $1M-$10M direct plus comparable revenue at risk; reputational impact regional/national press cycle; operational impact one-three days; ESG impact rating-agency note or single-investor pressure.
  • High impact. Consumer harm to tens of thousands or material safety/rights infringement; regulatory exposure to mid-band penalty (Article 99(3) €15M / 3% turnover; FTC penalty; sectoral-regulator enforcement); financial impact $10M-$100M direct plus revenue at risk; reputational impact sustained national press plus customer churn measurable; operational impact week-long disruption; ESG impact rating downgrade or major-investor escalation.
  • Very-High impact. Consumer harm to hundreds of thousands plus / structural fundamental-rights violation / loss of life or safety injury; regulatory exposure to top-band penalty (Article 99(2) €35M / 7% turnover for Article 5 prohibited-AI; FTC structural relief; criminal referral); financial impact over $100M direct loss; reputational impact existential / customer-confidence rupture; operational impact multi-week to permanent; ESG impact equity-rating downgrade plus board accountability.

Color-coding convention. The 25 cells are colored using the dominance rule: Very-High likelihood × any impact ≥ Medium → crimson; High likelihood × High or Very-High impact → red; Medium likelihood × Very-High impact → red; Low likelihood × Very-High impact → amber; and so on. The convention is documented once, signed off by the audit committee, and used consistently across cyber, operational, AI, and emerging-risk heat-maps.

The Twelve Regulator-Grade AI Risk Scenarios for the Heat-Map

The audit committee is not interested in 200 scenarios. It is interested in the dozen-or-so scenarios that represent the bulk of regulatory, financial, reputational, and operational AI risk across the enterprise portfolio. The Acme set, defensible against challenge, cross-walked to specific EU AI Act articles, NIST AI RMF subcategories, ISO 42001 controls, and SR 11-7 expectations, is the following twelve. Each plots on the heat-map at a defensible likelihood-and-impact cell with named rationale.

  1. Hiring AI fairness slice failure. Annex III §4(a): employment, workers' management, access to self-employment. Article 99(3) penalty band €15M / 3% turnover. Cross-walk NIST Map 1.1 + Measure 2.11. Acme plot Q2 2026: Likelihood Medium (CAF amber on monthly slice-by-protected-attribute fairness test for the current vendor model since March; vendor remediation plan on schedule for June); Impact High (regulatory €15M / 3%, plus reputational national-press exposure plus EEOC/NYC LL 144 cross-walk). Cell: amber.
  2. Credit-scoring fairness disparity. Annex III §5(b), creditworthiness assessment. Article 99(3) penalty band €15M / 3% turnover. Cross-walk NIST Measure 2.11 + 3.2. Acme plot Q2 2026: Likelihood Low (CAF green; quarterly third-party fairness review on schedule; ECOA + state-level adverse-action compliant); Impact High (regulatory + financial + reputational). Cell: yellow.
  3. Customer-service prompt-injection data exfiltration. EU AI Act Article 15 + GDPR Article 32 (security of processing). Acme plot Q2 2026: Likelihood Medium (one red-team finding open from lesson 084's Q2 reporting; closure plan tracking but not yet complete; threat-intel signal elevated, indirect prompt-injection campaigns observed in the wild via support-ticket attachments); Impact High (financial + regulatory + reputational + GDPR Article 83(5) penalty band €20M / 4% turnover). Cell: amber.
  4. Agentic tool-misuse refund cascade. EU AI Act Articles 14 (human oversight) + 15 (robustness) + 26 (deployer obligation). Acme plot Q2 2026: Likelihood Medium (agentic refund-issuer has Tier-3 autonomy with per-action cap; one near-miss in February, agent attempted bulk-refund across 47 accounts before HITL gate held; remediation in place but pattern fragility persists); Impact High (financial direct loss + operational disruption + Article 26 deployer-obligation exposure + customer harm). Cell: amber.
  5. Foundation-model vendor lock-in / upstream upgrade cascade. EU AI Act Article 25(1)(a), substantial-modification cascade if vendor changes architecture or training data. Cross-walk lesson 043. Acme plot Q2 2026: Likelihood High (single-supplier on 11 of 17 production AI systems; vendor announced Q3 refresh; re-conformity cycle would impact 7 systems simultaneously); Impact High (operational + re-conformity cost + regulatory). Cell: red.
  6. GPAI Article 51 designation if internal fine-tune crosses systemic-risk threshold. EU AI Act Articles 51, 53, 55. Acme plot Q2 2026: Likelihood Low (internal fine-tune compute 0.8 × 10²⁵ FLOPs, under threshold; planned Q4 budget would lift to 1.2 × 10²⁵); Impact Very-High (designation triggers Article 53 documentation + Article 55 systemic-risk obligations including adversarial-testing-by-independent-personnel, model-evaluation submissions, incident reporting; estimated $8-15M Y1 compliance investment). Cell: amber.
  7. Article 73 serious-incident reporting late. EU AI Act Article 73, providers must report within 15 days (or 2 days for widespread infringement). Article 99(3) penalty band €15M / 3% turnover. Acme plot Q2 2026: Likelihood High (one late report on 22 April, the trigger for this exercise; root-cause was trigger-categorization ambiguity between 1L incident-response and 2L AI Risk Office; remediation operational test pending); Impact High (regulatory + reputational + cascading AC attention). Cell: red. Worst single scenario on the Acme Q2 heat-map.
  8. Shadow AI uncovered in enterprise. EU AI Act Article 4 (AI literacy) + Article 6 (classification) gap. Acme plot Q2 2026: Likelihood Medium (last enterprise discovery sweep in March identified 9 shadow AI tools across procurement, legal, and marketing; remediation in progress but new procurement quarter likely to introduce new instances); Impact Medium (regulatory exposure on classification + literacy + GDPR exposure if PII processing; financial impact contained but reputational uplift if disclosed). Cell: amber.
  9. NYC Local Law 144 bias audit miss. NYC Department of Consumer and Worker Protection - Automated Employment Decision Tools (AEDT) bias audit + notice obligations effective 5 July 2023 enforcement. Acme plot Q2 2026: Likelihood Low (annual bias audit completed February; AEDT notice posted; vendor model unchanged within 12-month window); Impact Medium (NYC fine $500-$1500 per violation per day + reputational + cross-jurisdictional spillover to California SB 7, Illinois HB 3773, Colorado AI Act 2026). Cell: yellow.
  10. EU AI Act Annex IV technical-documentation file stale. Article 11 (technical documentation) + Article 17 (quality management) + Article 18 (record-keeping). Article 99(3) penalty band. Acme plot Q2 2026: Likelihood Medium (Annex IV TDF refresh cycle is quarterly; Q1 refresh complete for 12 of 17 systems but 5 systems' TDFs still reflect Q4 2025 model versions; Article 25(1)(a) substantial-modification trigger possibly already crossed on 2 of those 5); Impact Medium (regulatory + cascading effect on conformity assessment + Article 49 declaration-of-conformity at risk). Cell: amber.
  11. ISO 42001 surveillance audit major finding. ISO/IEC 42001:2023 surveillance-audit cycle (Year 2 of three-year certification). Acme plot Q2 2026: Likelihood Low (Stage-1 + Stage-2 audit passed cleanly November 2025 per lesson 040; Year-2 surveillance scheduled October 2026; internal-audit pre-check planned September); Impact High (certificate suspension would cascade to vendor contracts containing ISO 42001 representations; commercial impact estimated $4-8M annually; reputational + competitive). Cell: yellow.
  12. Vendor SOC 2 + AI lapse cascading deployer obligation. EU AI Act Article 26; SOC 2 Type II refresh failure or qualified opinion on AI-control criteria. Acme plot Q2 2026: Likelihood Medium (3 of 14 vendors have SOC 2 refresh dates within Q3; one flagged in Q1 pre-audit with weaknesses on access to fine-tuning data); Impact Medium (Article 26 cascade + procurement cost + disruption if vendor swap required). Cell: amber.

Movement arrows, the 12-month trajectory. Every plotted scenario carries an arrow showing expected position 12 months forward based on current mitigation plans. Acme Q2 2026 arrows: Scenario 1 (hiring fairness) trending toward yellow as vendor remediation lands in June. Scenario 5 (vendor lock-in) trending toward amber as the multi-supplier diversification plan executes through Q3-Q4. Scenario 7 (Article 73 late) trending toward amber once the trigger-categorization remediation operational test completes in June. The other nine scenarios trend stable or improve by one band over the 12-month window. The arrow direction, not just the current cell, is the artifact the audit committee uses to test whether mitigation plans are credible.

The Eight-Section Heat-Map Briefing Document

The heat-map graphic is necessary but not sufficient. The audit-committee briefing pack wraps the graphic in seven supporting sections. Eight sections total, designed to fit a 12-15 minute presentation slot with 8-12 minutes of Q&A, and structured so the chair can carry the pack to the full board without modification.

  1. One-page narrative (top of pack). 200-300 words. The "story" the heat-map tells this quarter: portfolio size (17 AI systems for Acme Q2 2026), aggregate trajectory (improving / stable / deteriorating), worst point (Scenario 7), the three biggest movement arrows, the standing ask (decisions the audit committee is being asked to make). Written for the chair's pre-read on Sunday evening before Monday's meeting.
  2. Heat-map graphic (centerpiece). Single page. The 5×5 grid with the twelve scenarios plotted (numbered 1-12, color-coded by cell, with arrows). Legend on the side defining the likelihood + impact bands. A timestamp ("As of Q2 2026, refreshed 18 May 2026 by AI Risk Office; next scheduled refresh 17 August 2026; emergency-refresh provisions per protocol").
  3. Per-scenario one-line. Twelve lines, one per scenario. Each line: scenario name + plotted cell + one-sentence rationale + arrow direction + named accountable executive. Designed so an audit-committee member can scan the whole portfolio in 90 seconds.
  4. Mitigation table. One row per scenario. Columns: current mitigation status (on plan / behind plan / not yet started), Q3 milestone, Q4 milestone, named accountable (e.g., "VP Talent Tech for Scenario 1; CTO for Scenario 4"), evidence binder reference (e.g., "Annex IV TDF §6.2 for Scenario 3"). The mitigation table is the operational backbone, the heat-map says where the risks are; the mitigation table says what is being done about them.
  5. KRI vs appetite cross-walk (lesson 074). Six-to-twelve key risk indicators from the board-approved AI risk appetite statement plotted against current values and threshold breach signals. The audit committee uses this section to test whether the heat-map is consistent with the standing appetite ("if the heat-map shows red on Scenario 7 but appetite for Article 73 incidents was 0, why is appetite not breached"). A consistent answer reinforces credibility; an inconsistent answer is the question that consumes the second half of the agenda.
  6. Change-from-last-quarter. Side-by-side delta view: Q1 heat-map vs Q2 heat-map. Which scenarios moved cells, in which direction, why. New scenarios added (with rationale for the addition). Scenarios removed (with rationale for the removal, typically a scenario falls off when sustained mitigation collapses likelihood to Very-Low for two consecutive quarters). The change view is the artifact the chair uses to test "is the AI Risk Office actually tracking changes or just reissuing the same map."
  7. Asks and decisions. A short list, typically 2-5 items, of decisions the audit committee is being asked to make this quarter. Examples for Acme Q2 2026: (a) sign-off on the Scenario 7 remediation operational test by 30 June; (b) approval of $1.2M Q3 budget for the vendor diversification plan (Scenario 5); (c) approval of the Article 51 designation contingency plan (Scenario 6); (d) noting the standing trajectory. Decisions named explicitly so they can be captured in the minutes.
  8. Sign-off block. CRO sign-off + CAIO sign-off + AI Risk Office head sign-off + audit-committee chair sign-off + meeting date + version. The sign-off block is the evidence artifact that lands in the Annex IV record (Article 18 record-keeping) and is producible on subpoena, regulator information request (Article 89 templates), or insurance-claim discovery.

Governance cadence.

The heat-map is refreshed quarterly by the AI Risk Office (2L) with named inputs from: the Centralized AI Function (CAF, lesson 077) for portfolio-level fairness and bias signals; the AI red team (lesson 081 + 084) for adversarial-finding closure rates and severity distribution; Model Risk Management / Independent Model Validation (MRM/IMV, lesson 068) for model-risk-register entries and validation status; the Article 72 post-market monitoring function (lesson 080) for trigger-event signals and Article 73 incident history; the Data Protection Officer for GDPR-DPIA registry intersection; Internal Audit (3L) for prior-audit findings and remediation status; the procurement / vendor management function for vendor-concentration analysis and SOC 2 status; the threat-intelligence function for current adversary-tradecraft signals.

Presented to the audit committee semi-annually (Q2 and Q4 cycles), with quarterly interim updates to the AI Governance Committee (lesson 014). Emergency refresh on any of: Article 73 serious incident; ISO 42001 surveillance audit finding; substantial-modification trigger (Article 25(1)(a)); material litigation or regulator action; vendor SOC 2 qualified opinion; foundational-model vendor major upgrade announcement.

Six Common Failures + Fifteen Audit-Committee Questions to Anticipate

Six common heat-map failures.

  • Failure 1 - Qualitative only, no anchored definitions. "High" without a percentage band, "Severe" without a financial range. The Big-Four auditor or audit-committee chair presses on "what does High mean" and the AI Risk Office cannot answer. Remediation: every likelihood and impact band has anchored definitions per the calibration tables above; the calibration document is appended to the briefing pack.
  • Failure 2 - Static, never refreshed. The same heat-map is reissued quarter after quarter with no change. Audit committee concludes the AI Risk Office is not actually tracking risk, the artifact is theater. Remediation: quarterly refresh cycle with named inputs + change-from-last-quarter section + emergency-refresh provisions.
  • Failure 3 - Hides movement, point-in-time only. The map shows current cells but no trajectory arrows. The audit committee cannot tell whether mitigation plans are credible because forward direction is absent. Remediation: every scenario carries a 12-month forward arrow with named mitigations driving the direction.
  • Failure 4 - Ignores systemic risks. The heat-map plots twelve scenario-level risks but misses cross-cutting systemic exposures: vendor concentration (Scenario 5), shadow AI propagation (Scenario 8), GPAI threshold drift (Scenario 6). Remediation: include systemic scenarios explicitly; the twelve-scenario set above is designed to cover them.
  • Failure 5 - Divorced from risk appetite (lesson 074). The heat-map shows cells but there is no breach signal against the board-approved AI risk appetite. The audit committee cannot tell whether the picture is "within tolerance" or "out of tolerance." Remediation: the KRI vs appetite cross-walk section is mandatory in the briefing pack.
  • Failure 6 - Too granular, audit committee cannot absorb. 50+ scenarios plotted on a single 5×5 grid produces a visual that no committee member can read. Remediation: the consolidated twelve-scenario set; deeper granularity stays in the underlying risk register (which the heat-map references but does not display).

Fifteen audit-committee questions to anticipate.

The AI Risk Office prepares a pre-briefing deck (not shown in the audit-committee pack itself) with prepared one-paragraph responses to each of the following fifteen questions. The chair routinely asks 6-10 of them; preparation across all fifteen prevents the meeting being sidetracked.

  1. How does this compare to last quarter? Reference the change-from-last-quarter section; name 2-4 specific cell movements and the drivers.
  2. What's the worst single scenario right now? Acme Q2 2026: Scenario 7 (Article 73 late report), point to the cell and the remediation plan with operational test in June.
  3. What's our prepared response for the worst-case cell? The incident-response runbook for Article 73 (lesson 047) plus the trigger-categorization remediation playbook plus the standing crisis-communications plan.
  4. What mitigations are scheduled this quarter and next? Reference the mitigation table; name Q3 and Q4 milestones with accountables.
  5. What's our insurance coverage on AI? Reference the cyber + tech-E&O + emerging AI-specific endorsements; note the coverage gap (typically reputational and regulatory penalty are excluded or sub-limited).
  6. Where are we within the standing AI risk appetite? Reference the KRI vs appetite cross-walk; name any current breaches and the standing response.
  7. How does Acme compare to peers? Reference industry incident-tracker data, sector-ISAC reports, peer-disclosure analysis from proxy statements; honest comparative answer is more defensible than reassurance.
  8. What are the unknown unknowns? Reference horizon-scanning function output: emerging regulatory developments (e.g., Article 89 information-request templates, CAISI updates, NIST AI RMF 2.0), emerging attack patterns from threat-intel, emerging operational dependencies.
  9. What is the heat-map missing? An honest answer naming 1-2 known gaps, typically scenarios deferred because likelihood data is not yet calibrated; deferred-scenario list maintained in the AI Risk Office shadow register.
  10. How does this tie to the cyber heat-map? Reference the explicit cross-links: Scenario 3 (prompt-injection exfiltration) ties to cyber-data-exfiltration scenarios; Scenario 5 (vendor lock-in) ties to cyber-third-party-risk scenarios. The two heat-maps share scenarios where appropriate, with sole ownership clarified.
  11. How does this tie to operational-risk? Reference the loss-event database integration (lesson 086 forthcoming): every realized AI incident lands in the loss-event database with the heat-map scenario reference; the database feeds the next quarter's likelihood calibration.
  12. What is the regulator-engagement posture? Reference the EU AI Office Article 89 information-request preparation, the CAISI Agent Standards Initiative engagement, the sector-regulator (FRB, OCC, FCA, BaFin) standing relationships.
  13. What is the GPAI provider designation contingency? Reference Scenario 6; name the trigger threshold (10²⁵ FLOPs), the compute-budget gating, the Article 51 designation playbook with Article 53 + Article 55 obligation costs.
  14. What is the substantial-modification posture under Article 25(1)(a)? Reference the substantial-modification change-control framework (lesson 043); name the standing test against vendor-driven changes (Scenario 5) and internal-fine-tune changes.
  15. What is the sign-off chain on this heat-map? Reference the sign-off block: CRO + CAIO + AI Risk Office head + audit-committee chair; producible on Article 89 information request, Article 18 record-keeping audit, and litigation discovery.

Worked Example: Acme Inc Q2 2026 Heat-Map to Audit Committee

Pulling the components together: the worked Acme heat-map presented to the audit committee on 22 May 2026, ninety-one days after the chair's Q1 ask.

Portfolio. Seventeen AI systems plotted: four high-risk Annex III systems (hiring AI, credit-scoring AI, fraud-detection AI under finance, agentic refund-issuer); seven limited-risk customer-facing systems (chat assistants, recommender engines, support copilots); five internal-tooling AI systems (engineering copilots, content-summarization, meeting-transcription, internal-search, document-drafting); one foundation-model in-house fine-tune (the candidate for Article 51 threshold under Scenario 6).

Worst point. Scenario 7 (Article 73 late report) plots at High likelihood × High impact = red cell. The driver: the 22 April incident where the trigger-categorization between 1L incident-response and 2L AI Risk Office took 11 days to resolve before the regulator was notified, landing 4 days past the Article 73 fifteen-day window. The remediation operational test is scheduled 27 June; trajectory arrow points to amber by Q3.

Three movement arrows toward amber. Scenario 1 (hiring fairness) red→amber as vendor remediation lands. Scenario 5 (vendor lock-in) red→amber as multi-supplier diversification executes through Q3-Q4. Scenario 7 (Article 73 late) red→amber as trigger-categorization remediation completes June.

Mitigation table extract (top 5 by penalty exposure).

ScenarioStatusQ3 milestoneQ4 milestoneAccountable
7 - Article 73 late reportOn planOperational test of trigger-cat playbook, 27 JuneQuarterly drill cadence operationalCRO + Head of AI Risk Office
5 - Vendor lock-in cascadeOn planSecond-supplier sign + cutover plan for 3 systemsActive load-balancing on 5 systemsCTO + Head of Procurement
1 - Hiring fairness sliceOn planVendor remediation deployed; CAF greenIndependent fairness audit refreshVP Talent Tech + CAF Lead
4 - Agentic refund cascadeOn planTier-3→Tier-2 autonomy de-escalation pending HITL reviewMulti-agent topology hardened per ASI06CTO + Agentic Systems Lead
6 - GPAI Article 51 designationOn planCompute-budget gating board approvalArticle 53/55 obligation cost-benefit briefingCAIO + CFO

KRI vs appetite cross-walk extract. Board-approved appetite from lesson 074: zero late Article 73 reports per year (current breach, 1 in trailing 12 months; corrective action plan operational). Zero substantial-modification non-conformities under Article 25(1)(a) (current breach, 2 Annex IV TDFs stale; remediation in progress). Less than 5% material findings on quarterly red-team campaigns (current Q2 6.2%, slightly out of tolerance; trending in toward 4% by Q4). Less than 2 amber KRIs sustained across consecutive quarters (current 2, on threshold). The picture: out of appetite on two indicators, within on the other eight, with stated mitigation plans for each.

Asks and decisions to the audit committee. (1) Sign-off on the Scenario 7 remediation operational test by 30 June 2026. (2) Approval of $1.2M Q3 budget for the Scenario 5 vendor-diversification execution. (3) Approval of the Scenario 6 Article 51 designation contingency plan including the compute-budget gating mechanism. (4) Note the trajectory: three red-to-amber arrows, eight stable, six green. (5) Note the next emergency-refresh trigger: any of (a) a second Article 73 incident before September, (b) a substantial-modification trigger on a critical vendor model, (c) an ISO 42001 surveillance finding above minor.

Sign-off. CRO signed 16 May 2026; CAIO signed 17 May; AI Risk Office head signed 17 May; audit-committee chair signed at the meeting 22 May with the four decisions captured in the minutes. The heat-map and the eight-section pack are filed in the Annex IV evidence binder (Article 18 record-keeping) and producible on Article 89 information request, regulator-engagement requests, M&A due-diligence (the artifact features in the Acme strategic-transaction data room), litigation discovery, and insurance-claim documentation.

Cross-walk summary. EU AI Act Articles 6 + 9 + 11 + 17 + 25 + 26 + 27 + 51 + 53 + 55 + 71 + 72 + 73 + 99; NIST AI RMF Govern 1.1 + 1.5 + 2.1 + 3.1 + 4.1 + 5.1 + 6.1 and Map 1-5 and Manage 1.1 + 1.3 + 2.1 + 4.3; ISO/IEC 42001:2023 A.3 (organizational context) + A.5 (leadership) + Clause 6 planning; SR 11-7 + PRA SS1/23 governance pillar. The heat-map is the artifact that converts those framework citations into a board-readable picture and a defensible audit-committee deliverable. The next lesson (086, FAIR loss-event reserve modeling) takes the heat-map's plotted scenarios and converts them into quantified loss-event reserves so the audit committee can size risk capital alongside the qualitative picture.

Key Takeaways

  • The AI risk heat-map is a 2026 audit-committee expectation, not a nice-to-have. SEC disclosure expectations, Dodd-Frank §165 enhanced prudential standards, SR 11-7 model-risk governance, EU AI Act Articles 9 + 17, and board AI-subcommittee charter amendments all converge on a single defensible 5×5 visual across the enterprise AI portfolio.
  • Anchored definitions are non-negotiable. Likelihood bands (Very-Low <2%/yr; Low 2-10%; Medium 10-25%; High 25-60%; Very-High >60%) and impact bands (combining six sub-impacts: consumer harm, regulatory exposure, financial, reputational, operational, ESG/strategic) defended by named data sources are the difference between a credible heat-map and one that collapses under Big-Four challenge.
  • The twelve-scenario set is the absorbable form. Twelve regulator-grade AI scenarios (from hiring fairness to GPAI Article 51 designation to Article 73 late reporting to ISO 42001 surveillance) plotted with rationale and 12-month movement arrows is the right granularity; 50 scenarios is unreadable, 3 is unconvincing.
  • The eight-section briefing wraps the graphic. Narrative + heat-map + per-scenario one-line + mitigation table + KRI vs appetite + change-from-last-quarter + asks and decisions + sign-off, the format that fits a 12-15 minute audit-committee slot with 8-12 minutes of defensible Q&A.
  • Six common failures collapse the artifact. Qualitative-only definitions; static / never refreshed; point-in-time without trajectory; ignores systemic risks; divorced from risk appetite (lesson 074); too granular. The disciplined heat-map avoids all six.
  • Fifteen audit-committee questions to anticipate. Prepared one-paragraph responses on comparison to last quarter, worst single scenario, prepared response, mitigation cadence, insurance, appetite cross-walk, peer comparison, unknown unknowns, missing pieces, cyber tie-in, operational-risk tie-in, regulator engagement, GPAI contingency, substantial-modification posture, sign-off chain, the chair will ask 6-10 of these.
  • Governance is quarterly with emergency-refresh. Refreshed by AI Risk Office (2L) with named inputs from CAF, red team, MRM/IMV, Article 72 PMM, DPO, Internal Audit, procurement, threat-intel. Presented to audit committee semi-annually; emergency refresh on Article 73 incident, ISO 42001 finding, substantial-modification trigger, material regulator action, vendor SOC 2 qualified opinion.
  • The heat-map is the qualitative half; FAIR loss-event modeling (lesson 086) is the quantitative half. The audit committee uses the heat-map to see the picture and the FAIR-derived loss-event reserves to size the capital. Together they form the defensible AI-portfolio risk artifact that ties to risk appetite, regulatory exposure, and board-level decision rights.